VW Storefront WordPress Theme Missing Authorization Vulnerability in Settings Reset Function
Vulnerability
A vulnerability exists in the VW Storefront theme for WordPress, all versions through 0.9.9, allowing unauthorized data modification. The issue arises from a missing capability check in the vw_storefront_reset_all_settings() function. This flaw enables authenticated attackers with Subscriber-level access and above to reset the theme's settings.
Impact
Exploitation of this vulnerability allows authenticated users to reset the VW Storefront theme settings, potentially leading to unauthorized changes in the site's appearance or functionality.
Remediation
Users can update to VW Storefront version 1.0.0 or a newer patched version to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
